Anti-Malware Engine Selection via Detection Intelligence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing anti-malware solutions face challenges in effectively detecting and combating constantly evolving malware, as they rely on signature-based detection methods that require frequent updates and can lead to performance issues when using multiple engines simultaneously, resulting in inconsistent protection across different malware strains.
Innovation Solution
A method is introduced to select a subset of anti-malware engines based on current detection intelligence and operational effectiveness, using information from various sources to rank engines and activate only the most effective ones, thereby balancing detection capabilities and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple anti-malware engines are used simultaneously, then malware detection capability is improved, but system performance deteriorates
Solution Approach 1:
The system dynamically selects and activates anti-malware engines based on real-time detection intelligence and operational effectiveness data. Instead of running all engines simultaneously, the system adapts its configuration by activating only the most effective engines for current malware threats, thereby maintaining high detection capability while optimizing system performance
Solution Approach 2:
The system changes operational parameters by adjusting which anti-malware engines are active based on detected malware characteristics and engine effectiveness metrics. This parameter adjustment allows the system to optimize the balance between detection capability and performance by selecting the appropriate subset of engines for each operational context
2Reliability
If all anti-malware engines are activated, then detection coverage is improved, but device complexity increases
Solution Approach 1:
The system extracts and activates only the necessary subset of anti-malware engines based on current detection needs and effectiveness data. By taking out only the relevant engines rather than activating all available engines, the system maintains comprehensive detection coverage for prevalent threats while reducing the complexity of managing multiple simultaneous engine operations
3Measurement precision
If signature-based detection is used, then detection accuracy is improved, but adaptability to new malware deteriorates
Solution Approach 1:
The system performs preliminary actions by maintaining multiple anti-malware engines with different detection capabilities and methodologies. This preparation allows the system to quickly switch between engines or activate specific engines that are effective against new or evolving malware strains, improving adaptability while maintaining detection accuracy through the availability of multiple specialized engines
Solution Approach 2:
The system changes detection parameters by selecting different anti-malware engines based on the characteristics of detected malware. This parameter change allows the system to adapt its detection approach - using signature-based engines for known threats and alternative detection methods for new or evolving malware, thereby maintaining both accuracy and adaptability
Data Source
AI summary
Selecting one or more applications from the plurality of similar or near redundant applications to activate. A method includes retrieving information about current characteristics of one or more applications. The method further includes retrieving information about a current computing operational landscape. Based on the information about current characteristics of one or more applications and the information about a current computing operational landscape, the method further includes creating a ranking of applications. The rankings are made available to a system with a plurality of applications with similar or near redundant functionality. At the system, one or more of the applications in the plurality of applications are selected to activate based on the ranking of applications.


